Collection And Enrichment Layer - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

management service to allow users to define objects using metadata. Additional services include
Correlation, Query Manager, Workflow, Event Visualization, Incident Response, Health, Advisor,
Reporting and Administration.
Sentinel Logical Layers
Figure A-8
The presentation layer renders the application interface to the end user. A comprehensive dashboard
called the Sentinel Control Center offers an integrated user workbench consisting of an array of
seven different applications accessible through a single common framework. This cross-platform
framework is built on Java
logic components – real-time interactive graphs, actionable incident response, automated
enforceable incident workflow, reporting, incident remediation against known exploits and more.
Each of the layers are illustrated in the figure above and subsequently discussed in detail in the
following sections.
A.4.1 Collection and Enrichment Layer
Event Source Management (ESM) provides tools to manage and monitor connections between
Sentinel and third-party event sources. Events are aggregated using a set of flexible and configurable
Collectors, which collect data from a myriad of sensors and other devices and sources. User can use
pre-built Collectors, modify existing Collectors or build their own Collectors to ensure the system
meets all requirements.
Data aggregated by the Collectors in the form of events is subsequently normalized and transformed
into XML format, enriched with a series of metadata (that is, data about data) using a set of business
relevance services and propagated to the server-side for further computational analysis using
message bus platform. The Collection and Enrichment layer consists of the following components:
Connectors and Collector
Collector Manager and Engine
Collector Builder
Connectors and Collectors
A Connector is a concentrator or multiplexed adapter that connects the Collector Engine to the
actual monitored devices.
1.4 standards and provides a unified view into independent business
TM
Sentinel Architecture 453

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents